CVE-2015-3414 describes a denial-of-service vulnerability in SQLite versions prior to 3.8.9, affecting products like Apple, Canonical, Debian, and PHP. This flaw stems from improper dequoting of collation-sequence names, allowing an uninitialized memory access and application crash via a crafted COLLATE clause in a SELECT statement. With a CVSS score of 7.5, this vulnerability is network-exploitable with low complexity and no authentication required, potentially leading to partial confidentiality, integrity, and availability impacts. While there is no evidence of active exploitation, nor publicly available exploit code in Metasploit or ExploitDB, the vulnerability has received some community discussion and media coverage, notably an Apple iTunes patch.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.8.8.3CPE matchmatch criteria | cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:* | ||
10.10.5CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.10.5:*:*:*:*:*:*:* | ||
1.0.1CPE matchmatch criteria | cpe:2.3:o:apple:watchos:1.0.1:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.